Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3648 to the following vulnerability: Name: CVE-2009-3648 URL: http://cve.mitre.org /cgi-bin/cvename.cgi?name=CVE-2009-3648 Assigned: 20091009 Reference: MISC: https://www.madirish.net/ Reference: BID:36584 Reference: URL: Reference: XF:servicelinks-content-type- xss(53633) Reference: URL: Cross- site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names. Checked drupal-service_links in CVS and this affects Fedora 10, 11, and rawhide.

Fedora 10 Update: drupal-service_links-6.x.1.0-5.fc10

October 13, 2009
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-10445
2009-10-14 00:46:50
--------...

Summary

Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3648 to the following vulnerability: Name: CVE-2009-3648 URL: http://cve.mitre.org /cgi-bin/cvename.cgi?name=CVE-2009-3648 Assigned: 20091009 Reference: MISC: https://www.madirish.net/ Reference: BID:36584 Reference: URL: Reference: XF:servicelinks-content-type- xss(53633) Reference: URL: Cross- site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names. Checked drupal-service_links in CVS and this affects Fedora 10, 11, and rawhide.

Change Log

References

Update Instructions

Severity

Related News